{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:10:10Z","timestamp":1755882610357,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T00:00:00Z","timestamp":1722297600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7,30]]},"DOI":"10.1145\/3664476.3670912","type":"proceedings-article","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T12:35:50Z","timestamp":1721910950000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["A Framework for Managing Separation of Duty Policies"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-1097-4967","authenticated-orcid":false,"given":"Sebastian","family":"Groll","sequence":"first","affiliation":[{"name":"University of Regensburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7082-000X","authenticated-orcid":false,"given":"Sascha","family":"Kern","sequence":"additional","affiliation":[{"name":"Nexis GmbH, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8432-6755","authenticated-orcid":false,"given":"Ludwig","family":"Fuchs","sequence":"additional","affiliation":[{"name":"Nexis GmbH, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1338-9003","authenticated-orcid":false,"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Regensburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,7,30]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Conducting semi-structured interviews. Handbook of practical program evaluation","author":"Adams C","year":"2015","unstructured":"William\u00a0C Adams. 2015. Conducting semi-structured interviews. Handbook of practical program evaluation (2015), 492\u2013505."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382913"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101802"},{"key":"e_1_3_2_1_4_1","unstructured":"Basel Committee on Banking Supervision. 2011. Basel III - A Global Regulatory Framework for More Resilient Banks and Banking Systems. Bank for International Settlements."},{"key":"e_1_3_2_1_5_1","unstructured":"Khalid Bijon R. Krishman and R. Sandhu. 2013. Constraints specication in attribute based access control. SCIENCE 2 (01 2013) 131\u2013144."},{"key":"e_1_3_2_1_6_1","unstructured":"Bundesanstalt f\u00fcr Finanzdienstleistungsaufsicht. 2024. Versicherungsaufsichtliche Anforderungen an die IT (VAIT)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDEW.2007.4401062"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133058.1133077"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICYCS.2008.223"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1063979.1063986"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.2017.8167833"},{"key":"e_1_3_2_1_12_1","unstructured":"Deutsche Bundesbank. 2017. Bankaufsichtliche Anforderungen an die IT (BAIT). Available at https:\/\/www.bundesbank.de\/de\/aufgaben\/bankenaufsicht\/einzelaspekte\/risikomanagement\/bait\/bankaufsichtliche-anforderungen-an-die-it-598580."},{"key":"e_1_3_2_1_13_1","unstructured":"Ludwig Fuchs Michael Kunz and G\u00fcnther Pernul. 2014. Role model optimization for secure role-based identity management. (2014)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1998.674833"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2008.71"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-162"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420936.2420938"},{"key":"e_1_3_2_1_18_1","volume-title":"Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach. In IFIP Annual Conference on Data and Applications Security and Privacy. Springer, 223\u2013242","author":"Kern Sascha","year":"2023","unstructured":"Sascha Kern, Thomas Baumer, Ludwig Fuchs, and G\u00fcnther Pernul. 2023. Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach. In IFIP Annual Conference on Data and Applications Security and Privacy. Springer, 223\u2013242."},{"volume-title":"Information Assurance in Computer Networks, Vladimir\u00a0I","author":"Knorr Konstantin","key":"e_1_3_2_1_19_1","unstructured":"Konstantin Knorr and Harald Weidner. 2001. Analyzing Separation of Duties in Petri Net Workflows. In Information Assurance in Computer Networks, Vladimir\u00a0I. Gorodetski, Victor\u00a0A. Skormin, and Leonard\u00a0J. Popyack (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 102\u2013114."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/266741.266749"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2018.11.004"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1237500.1237501"},{"volume-title":"Specifying Separation of Duty Constraints in BPEL4People Processes","author":"Mendling Jan","key":"e_1_3_2_1_23_1","unstructured":"Jan Mendling, Karsten Ploesser, and Mark Strembeck. 2008. Specifying Separation of Duty Constraints in BPEL4People Processes. In Business Information Systems, Witold Abramowicz and Dieter Fensel (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 273\u2013284."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1377836.1377840"},{"key":"e_1_3_2_1_25_1","volume-title":"Sarbanes-Oxley Act of","author":"One Hundred Seventh\u00a0Congress of\u00a0the United States\u00a0of America. 2002.","year":"2002","unstructured":"One Hundred Seventh\u00a0Congress of\u00a0the United States\u00a0of America. 2002. Sarbanes-Oxley Act of 2002. Pub. L. No. 107-204, 116 Stat. 745."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/990036.990054"},{"volume-title":"International school on foundations of security analysis and design","author":"Samarati Pierangela","key":"e_1_3_2_1_27_1","unstructured":"Pierangela Samarati and Sabrina\u00a0Capitani de Vimercati. 2000. Access control: Policies, models, and mechanisms. In International school on foundations of security analysis and design. Springer, 137\u2013196."},{"volume-title":"Advances in computers. Vol.\u00a046","author":"Sandhu S","key":"e_1_3_2_1_28_1","unstructured":"Ravi\u00a0S Sandhu. 1998. Role-based access control. In Advances in computers. Vol.\u00a046. Elsevier, 237\u2013286."},{"key":"e_1_3_2_1_29_1","volume-title":"Access control: principle and practice","author":"Sandhu S","year":"1994","unstructured":"Ravi\u00a0S Sandhu and Pierangela Samarati. 1994. Access control: principle and practice. IEEE communications magazine 32, 9 (1994), 40\u201348."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ENABL.2001.953406"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.1997.596811"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/11555827_5"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.35"},{"key":"e_1_3_2_1_34_1","unstructured":"U.S. Department of Health & Human Services. n.d.. American Health Insurance Portability and Accountability Act. https:\/\/www.hhs.gov\/hipaa\/index.html. Accessed: 2023-06-10."},{"key":"e_1_3_2_1_35_1","volume-title":"Wirtschaftsinformatik Proceedings 2009 39","author":"Wolf Patrick","year":"2009","unstructured":"Patrick Wolf and Nick Gehrke. 2009. Continuous compliance monitoring in ERP systems-A method for identifying segregation of duties conflicts. Wirtschaftsinformatik Proceedings 2009 39 (2009)."},{"volume-title":"Modeling of Task-Based Authorization Constraints in BPMN","author":"Wolter Christian","key":"e_1_3_2_1_36_1","unstructured":"Christian Wolter and Andreas Schaad. 2007. Modeling of Task-Based Authorization Constraints in BPMN. In Business Process Management, Gustavo Alonso, Peter Dadam, and Michael Rosemann (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 64\u201379."},{"volume-title":"Modeling of Task-Based Authorization Constraints in BPMN","author":"Wolter Christian","key":"e_1_3_2_1_37_1","unstructured":"Christian Wolter and Andreas Schaad. 2007. Modeling of Task-Based Authorization Constraints in BPMN. In Business Process Management, Gustavo Alonso, Peter Dadam, and Michael Rosemann (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 64\u201379."},{"volume-title":"Web Information Systems Engineering \u2013 WISE 2007 Workshops, Mathias Weske, Mohand-Sa\u00efd Hacid","author":"Wolter Christian","key":"e_1_3_2_1_38_1","unstructured":"Christian Wolter, Andreas Schaad, and Christoph Meinel. 2007. Deriving XACML Policies from Business Process Models. In Web Information Systems Engineering \u2013 WISE 2007 Workshops, Mathias Weske, Mohand-Sa\u00efd Hacid, and Claude Godart (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 142\u2013153."},{"volume-title":"Mining meaningful role-based and attribute-based access control policies. Ph.\u00a0D. Dissertation","author":"Zhongyuan Xu.","key":"e_1_3_2_1_39_1","unstructured":"Zhongyuan Xu. 2014. Mining meaningful role-based and attribute-based access control policies. Ph.\u00a0D. Dissertation. State University of New York at Stony Brook."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124271"}],"event":{"name":"ARES 2024: The 19th International Conference on Availability, Reliability and Security","acronym":"ARES 2024","location":"Vienna Austria"},"container-title":["Proceedings of the 19th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3670912","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664476.3670912","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T16:53:06Z","timestamp":1755881586000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3670912"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,30]]},"references-count":40,"alternative-id":["10.1145\/3664476.3670912","10.1145\/3664476"],"URL":"https:\/\/doi.org\/10.1145\/3664476.3670912","relation":{},"subject":[],"published":{"date-parts":[[2024,7,30]]},"assertion":[{"value":"2024-07-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}